Privacy Policy
Version 1.0.2 — effective 27 August 2026
1. Who we are
RankGlide is operated by Dominik Hladík, IČO 08325561, registered address č.p. 106, 538 65 Řepníky, Czech Republic, a sole trader registered with the Městský úřad Vysoké Mýto trade office ("RankGlide", "we"). Contact: [email protected].
We are the controller for account, billing, telemetry, security, support, moderation and public-content processing. For ordinary personal data a business customer uploads to its private workspace, the customer is controller and we act as processor under the Business Data Processing Addendum.
2. What we process, why, and for how long
| Purpose | Data | Legal basis | Normal retention |
|---|---|---|---|
| Account and authentication | email, name, country, identifiers, login/security events | contract; legitimate interests in account security | account life; security telemetry 30 days |
| Workspaces and service delivery | content, memberships, conversations, configuration and usage | contract; for business uploads, processor instructions | account/workspace life; deleted production data within 30 days and expired backups within 90 days |
| Billing and tax | buyer type, country, Stripe customer/subscription references, invoices and transaction records | contract and legal obligations | generally 10 years where Czech accounting/tax law requires |
| Essential reliability and security | identifier-free error details, IP/security events, device/browser details | legitimate interests in secure, reliable operation | Sentry/security telemetry 30 days; detailed MCP/audit events 90 days |
| Optional analytics | page use, performance traces, replay and RankGlide viewer identifier | consent | revoke at any time; raw analytics and viewer identifiers no longer than 13 months |
| Public embeds | daily aggregate view count and embedding origin, without a persistent viewer identifier | legitimate interests in service measurement and abuse prevention | raw records 13 months, then aggregates |
| Support and complaints | messages, contact details and related evidence | contract; legitimate interests; legal claims | case life plus 3 years, longer if a claim requires |
| Public content and moderation | published content, reports, decisions, statements of reasons, appeals | contract; legitimate interests; legal obligations | public content until removed; moderation records 3 years |
| Checkout attempts | country, buyer type, plan and technical status | steps to enter a contract; fraud prevention | unfulfilled attempts 30 days |
| Legal acceptance | accepted document versions, locale, country, buyer type, timestamp, immediate-performance request | contract and proof of compliance | contract life plus applicable limitation/accounting periods |
We do not sell personal information, share it for cross-context behavioural advertising, or send marketing communications at launch. We do not intentionally process children’s data. Do not upload special-category, highly sensitive, health, biometric, criminal-conviction, government-ID or children’s data.
3. Sources and required information
We receive information from you, workspace members, your browser/device, embedding websites, authentication and payment providers, and reports about public content. Email is required to create a pending sign-in identity. Age confirmation, Terms acceptance, name and country are required to complete the account and use authenticated features. Billing country and payment information are separately required for paid service. If required information is not provided, we cannot complete the account, complete the purchase, meet tax/security duties, or provide the relevant feature.
4. Recipients and service providers
Access is limited to what is needed. Current processor categories include Supabase (database, authentication and Edge Functions), Firebase/Google (hosting), Resend (transactional email), Cloudflare Images (image delivery), Stripe (payments, billing and tax tooling), Sentry (errors and optional telemetry), Google Tag Manager/Google analytics tooling (optional analytics), OpenAI and Anthropic (AI features requested by a user). Payment providers and authorities may act as independent controllers for their own legal purposes.
Before publication and production payments, we verify production contracts, DPAs, subprocessors, regions, transfer mechanisms and backup retention. The current list and material changes are published in this notice or the DPA.
5. International transfers
We prefer EEA processing where production configuration permits. Some providers or support personnel may process data in the United States or other countries. Where EU/UK law requires, we use adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful safeguard, together with transfer-risk and security measures. Contact us for relevant safeguard information. Processing regions and transfer arrangements must be verified against the production accounts before launch.
6. Your choices and rights
The Privacy Center provides access, correction, portable export, deletion and objection controls. Depending on your law, you may also request restriction, withdraw consent, opt out of certain processing, or complain. Consent withdrawal does not affect earlier lawful processing. We may verify identity and may retain information that law requires.
Exports include account/profile data, consent history, memberships, social activity, conversations, connections and Personal-workspace content in JSON/CSV. Provider API keys and refresh tokens are never exported. Deletion has a reversible 30-day grace period; public Personal-workspace content is hidden immediately. Team ownership must be transferred or the Team workspace explicitly closed first. Details are described in the Terms.
Send requests to [email protected]. We normally respond within one month under EU/UK law or the period required locally. You may appeal a denied privacy request by replying to our decision.
7. Regional information
EU/EEA. You have GDPR rights and may complain to the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz, or your local supervisory authority.
United Kingdom. You have UK GDPR rights and may complain to the Information Commissioner’s Office.
United States. Subject to state law, you may request access, correction, deletion and portability and may appeal. We do not sell personal information or share it for targeted/cross-context behavioural advertising. We honour Global Privacy Control as a denial of optional analytics. We will not discriminate for exercising privacy rights. An authorised agent may submit a request where applicable, subject to verification.
Canada. You may request access and correction and challenge our compliance. We use consent where required and remain accountable for service providers. You may complain to the Office of the Privacy Commissioner of Canada.
Australia. You may access and correct personal information and complain to us. If unresolved, contact the Office of the Australian Information Commissioner.
New Zealand. You may access and correct personal information and complain to the Office of the Privacy Commissioner.
Mandatory local rights always apply and are not limited by this notice.
8. Security, deletion and automated tools
We use access controls, encryption in transit, least-privilege credentials, audit logging and incident procedures proportionate to risk. No system is perfectly secure. On scheduled deletion we remove Personal and selected Team workspaces, images, secrets, tokens, memberships, conversations and the Auth identity. Content owned by others remains, with audit references replaced by an anonymous tombstone. Only pseudonymised legal, billing, fraud and moderation evidence is retained where required.
AI output may be inaccurate. We do not use solely automated decisions that produce legal or similarly significant effects about users. AI providers receive prompts or workspace context only when the user invokes the relevant feature.
9. Cookies and changes
See the Cookie and Telemetry Notice. Material Terms or DPA changes require reacceptance. Privacy Policy changes are notified but are not represented as consent. Each version is published as an immutable snapshot with its effective date and digest.
10. Contact and complaints
Contact [email protected] with “Privacy” in the subject. Explain the issue and desired resolution. We will acknowledge, investigate and provide a reasoned response. You may also contact the regulator listed above without first contacting us.